IBM Tivoli Storage Manager Remote Client Agent Service Buffer Overflow

Strike ID:
D08-6q401
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
t
Variants:
3
Year:
2008

Description

This strike triggers a stack-based buffer overflow vulnerability in IBM Tivoli's Storage Manager. In the Remote Client Agent Service messages the Length1 and Length2 parameters are not properly validated before copying the NodeName into a 129 byte buffer. If either of these values are larger than this the stack will overflow.

CVE

Bid